Linux kernel是美国Linux基金会开源的一款操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于在CMD_NEW_PEER错误路径中未正确处理peer引用计数,调用ovpn_peer_release()直接释放而非通过ovpn_peer_put(),导致TCP连接上已持有引用的用户态调用者可能在free后内存上继续操作,最终造成释放后重用。以下版本受到影响:6.16版本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 11851cbd60ea1e5abbd97619d69845ead99303d6< 8298834912d76dbc82c12b6b4ab7590ed2bb8ae5 |
affected |
11851cbd60ea1e5abbd97619d69845ead99303d6< 0c3ef71879c0264de6c42463031d9e057da87840 |
affected | ||
11851cbd60ea1e5abbd97619d69845ead99303d6< 1fef6614673ff0846d30acdeeaf3cf98bb5f6116 |
affected | ||
6.16 |
affected | ||
< 6.16 |
unaffected | ||
6.18.34≤ 6.18.* |
unaffected | ||
7.0.11≤ 7.0.* |
unaffected | ||
7.1≤ * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-63795 | 10.0 CRITICAL | 9p: avoid putting oldfid in p9_client_walk() error path |
| CVE-2026-64033 | 9.8 CRITICAL | RDMA/rtrs: Fix use-after-free in path file creation cleanup |
| CVE-2026-63994 | 9.8 CRITICAL | tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]() |
| CVE-2026-63993 | 9.8 CRITICAL | vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() |
| CVE-2026-64142 | 9.8 CRITICAL | ksmbd: close durable scavenger races against m_fp_list lookups |
| CVE-2026-64102 | 9.8 CRITICAL | RDMA/siw: Reject MPA FPDU length underflow before signed receive math |
| CVE-2026-53399 | 9.8 CRITICAL | nfsd: release layout stid on setlease failure |
| CVE-2026-53398 | 9.8 CRITICAL | NFSD: Fix SECINFO_NO_NAME decode error cleanup |
| CVE-2026-64061 | 9.8 CRITICAL | netfs: Fix early put of sink folio in netfs_read_gaps() |
| CVE-2026-64089 | 9.8 CRITICAL | batman-adv: tt: fix negative last_changeset_len |
| CVE-2026-64091 | 9.8 CRITICAL | batman-adv: tt: fix TOCTOU race for reported vlans |
| CVE-2026-64025 | 9.8 CRITICAL | bpf, skmsg: fix verdict sk_data_ready racing with ktls rx |
| CVE-2026-64125 | 9.8 CRITICAL | net: bcmgenet: keep RBUF EEE/PM disabled |
| CVE-2026-64066 | 9.8 CRITICAL | netfs: Fix netfs_read_to_pagecache() to pause on subreq failure |
| CVE-2026-64132 | 9.8 CRITICAL | ipv6: ioam: refresh hdr pointer before ioam6_event() |
| CVE-2026-64136 | 9.8 CRITICAL | smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() |
| CVE-2026-63979 | 9.8 CRITICAL | net/handshake: hand off the pinned file reference to accept_doit |
| CVE-2026-63887 | 9.8 CRITICAL | scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf |
| CVE-2026-63978 | 9.8 CRITICAL | net/handshake: Drain pending requests at net namespace exit |
| CVE-2026-63808 | 9.8 CRITICAL | exfat: fix potential use-after-free in exfat_find_dir_entry() |
Showing top 20 of 429 CVEs. View all on vendor page → →
No comments yet